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Abstract 

An effective asymmetric watermarking procedure has been 
recently devised in literature, named Transformed-key 
Asymmetric Watermarking (TKAW). A weakness point of 
this system is its vulnerability against projection attacks, as 
well shown by Chen and Ye. This work discusses a modified 
version of the TKAW to provide robustness against 
projection attacks, by means of a non-linear transformation, 
without increasing the computational complexity of the 
original method but with the same performances. 
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Introduction 

Digital watermarking of multimedia contents has 
become a very active research area over the last 
several years ( Fit , 2012; Benedetto and Giunta, 2011; 
Bonuccelli et al, 2007; Li and Hung, 2011). In a 
networked environment like the World Wide Web, the 
crucial issue to be satisfied is the necessity to answer 
the ever-growing need to protect the intellectual 
property (copyright) of digital still images, video 
sequences, and audio from piracy attacks, maintain a 
high Quality of Service (QoS) of the communication 
link ( Ahmed et al, 2006; Benedetto et al, 2009, Campisi et 
al, 2002). The aim of a controlled distribution of 
multimedia data can be reached developing suited 
signal processing techniques, such as digital 
watermarking ( Benedetto et al, 2007; Benedetto et al, 
2005; Zang and Zhou, 2010). Although copyright 
protection was the very first application of 
watermarking, different uses have been recently 
proposed in the literature ( Benedetto et al, 2012b). 
Fingerprinting, broadcast monitoring, data 
authentication, multimedia indexing, content-based 
retrieval applications are only a few of the new 
applications where watermarking can be usefully 
employed ( Boato et al, 2008; Benedetto et al, 2011). Most 


of these watermarking schemes are symmetric 
watermarking procedures meaning that the same key 
is used for watermark embedding and extraction, 
allowing piracy attacks when the watermark is known 
by a third party and can be easily removed ( Ahmed and 
Syial, 2005; Xie et al, 2007). As a consequence, new 
schemes of asymmetric watermarking have been 
recently proposed in literature (see for example: Boato 
et al., 2008; Boato et al., 2007; Boato et al., 2006; Mi He and 
Lizhi Cheng, 2008; Jun et al., 2007; Jun and ]un, 2009; Gui 
and Chen, 2006a; Gui and Chen, 2006b; Furon and 
Duhamel, 2003; Tzeng et al., 2005). In particular, an 
asymmetric watermarking procedure has been 
devised by ( Choi et al, 2004) named transformed-key 
asymmetric watermarking (TKAW) system, in which 
two different keys are used for watermark embedding 
(i.e. encoding) and extraction (i.e. decoding), 
respectively. The TKAW scheme renders asymmetry 
through a transform matrix (i.e. a linear 
transformation). The asymmetric watermarking 
procedure proposed by ( Choi et al, 2004) is really 
effective but has a great weakness point, as it was 
demonstrated by ( Chen and Ye, 2006): in fact, the 
TKAW scheme is really vulnerable to projection attack. 
(Chen and Ye, 2006) show that for the TKAW system 
the inner product of the received signal and public key 
almost equals to zero and, as a result, it cannot resist 
projection attack. 

In this work, we propose a modified version of the 
TKAW procedure in order to provide robustness 
against projection attacks, by means of a non-linear 
transformation, without increasing the computational 
complexity of the original method and with the same 
performances. The remainder of this work is 
organized as follows. In Section II, we describe the 
modified TKAW scheme by means of a non-linear 
transformation, showing that this new procedure 
maintains the same system performance of the original 
method. Section III is about the security analysis of the 
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new scheme showing its robustness against the 
projection attack while Section IV briefly concludes the 
work. 

Modified TKAW System 

In the original TKAW system, ( Choi et al, 2004), the 
asymmetry is realized through a transformation 
matrix A. In particular, let m be a set of orthonormal 
sequences with i = 1, ..., k then the coding and 
decoding keys, Ws,i and w s ,j respectively, are obtained 


defeated by a standard projection attack as well shown 
in ( Chen and Ye, 2006). 

We propose here a new modified version of this 
algorithm in which the asymmetry is given by a non- 
linear transformation, allowing the same system 
performance and more robustness against the 
projection attack. More in details, following the same 
mathematical approach of ( Choi et al, 2004), we 
modify the encryption and decryption keys, 
respectively, as follows: 



II M-l A-t 

with y s = L 4mJ , y p = A u i and where A is an 

n x n matrix and A- 1 denotes inverse transpose. The 
embedding process is then realized by means of the 
rule y = x + a -w si = x + a • y s • A- u i , where x is 

the host signal and a, the power of the mark, is a 
scaling factor that determines the watermark strength 
and is adjusted to a value that makes the watermark 
imperceptible. 

The decoding (i.e. watermark detection) process is a 
usual correlation process between the decoder input r 
and the decoding key w P .j (i.e. public detection). In 
particular, the decoder evaluates the inner product 
between r and iVp.j as follows: 

C j = w ‘ P j r = r p u'j A -'x + /pUj^ccy.Au, = 

= y p u j A 1 x + ay p y s u , j u i 

Then, by comparing C/ with the threshold 
T = (e[Ci]+2e[Cj J)/3, the watermark can be detected, 

where obviously £[•] denotes the expectation operator. 
Choi et al designed the system so that UjA~ l x ~ 0 

and Cj « ay y s u‘jU . The TKAW system is an 

efficient asymmetric watermarking system but, as we 
can see, it is based on a linear transformation by 
means of the transformation matrix A. Moreover, the 
TKAW also needs u'-A^x ~ 0, which means it can be 


where the asymmetry is now given by means of an 
exponential of the matrix A (non-linear 
transformation). To compare the modified version 
with the original TKAW, we employ a watermark 
insertion in the wavelet transform domain. As in ( Choi 
et al, 2004), we consider images of size 512 x 512, 
octave-band decomposed into seven sub-bands in two 
levels using Daubechies filters, and the private 
watermark is added in the three mid-frequency sub- 
bands. Fig. 1 shows here the visual comparison 
between the Lena image watermarked with the 
original TKAW system (PSNR = 42.6 dB) and with the 
modified algorithm (PSNR = 40.86 dB): we obtain a 
negligible difference of less than 4% on the PSNR. 
Then, we have matched in our simulation results the 
performance of the original TKAW system obtaining 
the same performance, in terms of robustness against 
public attacks, as shown in details in the following. 

In particular, regarding the analysis about public 
attacks, we consider as in ( Choi et al, 2004) that an 
attacker tries to confuse the public detector by 
subtracting a properly scaled public key ji-w v ,i 
obtaining y = x + a -w si — ft ■ W p , where // is a 

constant value. The detector's output becomes 
Cj. = w' p t y. Now, considering 

w ‘ P j w s,i =rs7 P (A~ ,u j){Au i ) = pS ij where S y is the 
Kronecker Delta and p is the correlation coefficient 
between Ws,i and w P ,j, and denoting the cross- 
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correlation values among the two watermarks by & 
and £p respectively, we can now re-write the detector's 
output as: 


a) 



FIG. 1 LENA IMAGE: A) ORIGINAL TKAW WATERMARKED; B) 
MODIFIED TKAW WATERMARKED 


c 


J 


[~ap-p 

I* -AS 


if j = i 

if j * i 


(4) 


assuming the correlation between the host signal and 
the watermark sufficiently small, as in ( Choi et al, 
2004). The influence of this attack can be described in 
terms of the parameter (:>, which is 0 if there is no 
public attack. The merit of the original TKAW system, 
which holds on also in its modified version, in relation 
to the attacks is in that watermark detection by private 
key is still possible when the public detection is 
disabled. As done before with the public key, the 
correlation output in the detection using the private 
key is as follows: 


[ w[ f y ~a- ftp if j = i 

Cj=\ s f (5) 

[w ! s j y » a £ s if j* i 

Obviously, the two (public and private) keys must 
obey to the same requirements of the original 
algorithm in order to perform the same effectiveness 
and robustness. In particular, the matrix A must be 
chosen in order to have the correlation coefficient 
p= 0.5, as well depicted in ( Choi et al, 2004). This 
requirement is of fundamental importance because 
attackers cannot disable both the public detection and 
the private detection at the same time. This feature 
provides additional security to the modified TKAW 
system. This is illustrated in Fig. 2 where we have 
obtained the same results of the Fig. 1 published in 
(Choi et al, 2004), showing that the modified TKAW 
system holds the same performance as the original 
approach, versus different values of the parameter <s> . 
In the following Section, we describe how the 
modified TKAW system can outperform the projection 
attack. 

Security Analysis about Projection Attack 

One of the weakness points of the original algorithm 
TKAW is its vulnerability against projection attacks as 
well discussed by ( Chen and Ye, 2006), since the 
asymmetry of the TKAW system is realized by means 
of a linear transformation. (Chen and Ye, 2006) discuss 
how to find the closest un-watermarked y to the 
watermark-embedded signal y and they also show 
that the difference between y and y is less than the 
watermark energy a. Therefore, the TKAW system 
cannot resist projection attacks. Here, we explain that 
using the modified TKAW system, the difference 
between y and y is greater than the power of the 
mark, a, and therefore the algorithm is robust against 
projection attacks In particular, following the same 
methodological approach of (Chen and Ye, 2006), we 
denote with r = y + n the received signal (which is the 
watermark-embedded signal y combined with an 
additive noise n) and with y = r + tw the un- 

watermarked signal, i.e. the projection of y in the same 
hyperplane on which x falls, (Chen and Ye, 2006). As 
well depicted by (Chen and Ye, 2006), the original 
TKAW system must satisfy the following condition: 

(w pJ ,x) = 0 (6) 
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thus, with 
have 

finally obtaining: 


projection attack 


we 


have / WpJ ,y) = (w pJ f (r + tw ] 


/) K-J 


: w II =0 / 
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(7) 
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FIG. 2 PRIVATE AND PUBLIC DETECTION AGAINST PUBLIC ATTACK WITH CORRELATION COEFFICIENT p = 0.5 


that is the closest solution against watermark- 
embedded signal. Moreover, (Chen and Ye, 2006 ) 
illustrated that the difference between y and y is less 
than the watermark energy a: 

| y - y 1 ^ ||. y - *|| = I aw si || = \a\ (8) 

In particular, with the original TKAW system the 
difference in (8) equals the power of the watermark 
and the system cannot resist projection attack. This is 
not more valid using the modified version of the 
TKAW system we propose. In fact, since the 
asymmetry is now given by means of a non-linear 
transformation, the difference between y and y is 
greater than the parameter a. In particular, with our 
modified algorithm we obtain the following value 
||_y — 5>|| = 9 with a = 0.1. Therefore, we can conclude 
that: 

||v-v||>|a| (9) 

This means that the obtained un-watermarked image 
is really different from the watermarked one, i.e. the 
modified TKAW system can now resist projection 
attacks. 

Conclusions 

This work has devised a modified version of the 
TKAW procedure in order to provide robustness 
against projection attacks, by means of a non-linear 
transformation. We have matched the performance of 


the original TKAW system obtaining the same 
robustness against public attacks. In particular, the 
merit of the original TKAW system, which holds on 
also in its modified version, is represented by the fact 
that watermark detection by private key is still 
possible when the public detection is disabled. 

On the other hand, one of the weakness points of the 
original TKAW was its vulnerability against projection 
attacks, since the asymmetry was realized by means of 
a linear transformation. Here, we have shown that the 
modified TKAW system can now resist projection 
attacks. In fact, since the asymmetry is now given by 
means of a non-linear transformation, the difference 
between the watermarked signal y and its closest un- 
watermarked copy is greater than the watermark 
energy a. 
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